Privacy Policy
Last updated: June 19, 2026
1. Who This Policy Applies To
This Policy applies to:
- Website visitors: people who browse the Site or submit a form (for example, a demo request or contact form).
- Clients: businesses that subscribe to the Services, and their authorized users.
- Callers and contacts: individuals who call, text, or otherwise interact with an AI receptionist that one of our Clients operates using the Services.
Our role differs depending on the data. When we collect information about website visitors and clients for our own purposes, we act as a data controller. When we process information contained in or generated by calls, messages, and bookings on behalf of a Client (for example, a caller’s name, phone number, call recording, or transcript), we act as a service provider / data processor on that Client’s behalf. In those cases, the Client is responsible for that data and for the legal basis to collect it, and our handling is governed by our agreement with that Client. If you are a caller and wish to exercise rights over data held by a business that uses Callixa, please contact that business directly (see Section 10).
2. Information We Collect
2.1 Information you provide to us
- Contact and inquiry details: name, business name, email, phone number, and any message you submit through a form on the Site.
- Account information: details provided when a Client registers for the Services, including business details, authorized user contacts, and login credentials.
- Configuration content: business information a Client supplies to configure their AI receptionist, such as services, hours, pricing rules, FAQs, transfer numbers, and after-hours behavior.
- Payment information: billing details processed through our payment processor. We do not store full card numbers ourselves; payments are handled by Stripe (see Section 6).
- Communications with us: records of your correspondence when you contact support or sales.
2.2 Information collected automatically
- Usage and device data: IP address, browser type, device identifiers, pages viewed, referring URLs, and timestamps.
- Cookies and similar technologies: used to operate the Site, remember preferences, and measure performance (see Section 8).
2.3 Call, message, and booking data (processed on behalf of Clients)
When the Services handle a call, text, chat, or booking for a Client, the following may be collected and processed on that Client’s behalf:
- Caller or contact name, phone number, email, and service address where provided;
- The reason for the contact and details of the request;
- Call recordings and transcripts, where recording is enabled;
- Appointment and booking details;
- Lead, contact, and conversation records synced to the Client’s CRM and calendar.
2.4 Information from third parties
We may receive information from service providers and integration partners that support the Services (for example, telephony, voice AI, CRM, calendar, and analytics providers) and from payment processors confirming transactions.
3. How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Site and the Services;
- Set up, configure, and support Client accounts and AI receptionists;
- Answer calls and messages, capture leads, book appointments, and route or transfer contacts as configured by the relevant Client;
- Process payments and manage subscriptions;
- Communicate with you about your account, support requests, security, and service updates;
- Monitor, analyze, and improve performance, reliability, and quality (including limited sampling of interactions for quality review);
- Detect, prevent, and address fraud, abuse, and security issues;
- Comply with legal obligations and enforce our agreements.
Legal bases (EEA/UK). Where the GDPR or UK GDPR applies and we act as a controller, we rely on: performance of a contract; your consent (which you may withdraw at any time); compliance with a legal obligation; and our legitimate interests in operating, securing, and improving our business, balanced against your rights.
4. Call Recording, AI Disclosure, and Consent
- AI disclosure. Calls and messages handled by the Services may be answered by an automated AI agent rather than a human. Clients are responsible for disclosing the use of AI to their callers where required by law.
- Recording. Where call recording is enabled, calls may be recorded and transcribed. Recording laws vary by jurisdiction; some require the consent of all parties. Clients are responsible for providing any required recording notice or obtaining consent, and we provide configuration options to support an announcement at the start of a call.
- Consumer interactions. If you are a caller, your interaction is handled on behalf of the business you contacted, and that business determines how your information is used. Contact that business to access, correct, or delete your information.
5. SMS and Text Messaging
If you opt in to receive text messages from us (for example, demo scheduling, onboarding, appointment confirmations, account and service notifications, or product updates and offers):
Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and you can reply HELP for assistance. We will not share your mobile information, including your phone number and your SMS opt-in and consent data, with third parties or affiliates for marketing or promotional purposes. Mobile opt-in and consent data is never sold, and it is not shared with any third parties except the messaging aggregators and service providers that help us deliver the text-messaging program.
6. How We Share Information
We do not sell your personal information for money. We share information only as described below.
- Service providers and subprocessors. We use trusted third-party service providers to deliver the Services. These fall into categories such as voice AI and conversation orchestration, telephony and messaging, text-to-speech, CRM and workflow automation, hosting and infrastructure, payment processing, and email delivery. These providers process information only to provide services to us and are bound by confidentiality and data protection obligations. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties for their own marketing or promotional purposes.
- Clients. Information generated through a Client’s AI receptionist is shared with that Client, who controls it.
- Legal and safety. We may disclose information to comply with law, legal process, or lawful requests, and to protect the rights, property, or safety of Callixa, our Clients, or others.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
- With your direction or consent. We share information when you ask us to or otherwise consent.
7. AI and Automated Processing
The Services use artificial intelligence to understand speech, generate responses, and take actions such as booking appointments. Decisions made by the AI (for example, whether to transfer a call to a human) are configured by the relevant Client. We do not use AI to make decisions that produce legal or similarly significant effects about you without a lawful basis. We do not use the content of Client calls to train general purpose AI models except as permitted by our Client agreements.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Site, remember your preferences, understand usage, and improve performance. You can control cookies through your browser settings; disabling some cookies may affect Site functionality. Where required by law, we will request your consent before placing non-essential cookies. For more detail, see our cookie banner, if provided.
9. Data Retention
We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements:
- Account and billing records: for the life of the account and as required by law afterward.
- Call recordings and transcripts: retained per the relevant Client’s settings and instructions; Clients may configure retention and deletion.
- Website and usage data: retained for a limited period for analytics and security.
When information is no longer needed, we delete or de-identify it.
10. Your Privacy Rights
Your rights depend on where you live and on our role with respect to the data.
If you are a caller or contact whose information was collected through a business that uses Callixa, that business controls your information. Please direct access, correction, or deletion requests to that business. We will assist that business in responding.
10.1 EEA / UK residents
Where we act as a controller, you may have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to processing; data portability; and withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
10.2 California residents (CCPA/CPRA)
Subject to exceptions, you may have the right to: know the categories and specific pieces of personal information we collect; know how it is used and shared; delete your personal information; correct inaccurate personal information; and not be discriminated against for exercising these rights.
- Categories we may collect include identifiers, commercial information, internet/network activity, geolocation, audio/electronic information (such as call recordings), and professional or business information.
- “Sale” and “sharing.” We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law.
10.3 How to exercise your rights
Submit a request to support@callixa.ai. We will verify your identity before responding and will respond within the timeframes required by applicable law. You may use an authorized agent where the law permits.
11. International Data Transfers
We are based in the United States, and we and our service providers may process information in the United States and other countries. Where we transfer personal data from the EEA, UK, or other regions with cross-border transfer restrictions, we rely on appropriate safeguards, such as Standard Contractual Clauses, where required.
12. Data Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and authorities as required by law.
13. Children’s Privacy
The Site and the Services are not directed to children, and we do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
14. Third-Party Links and Services
The Site may link to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
15. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where required, provide additional notice. Your continued use of the Site or Services after an update means you accept the revised Policy.
16. Contact Us
If you have questions about this Policy or our privacy practices, contact us at:
eDigitalCommerce L.L.C. (d/b/a Callixa.ai)
Email: support@callixa.ai